JN0-637 · Question #1
Which two statements are true about the procedures the Junos security device uses when handling traffic destined for the device itself? (Choose two.)
The correct answer is C. If the received packet is addressed to the ingress interface, then the device first examines the D. If the received packet is destined for an interface other than the ingress interface, then the device. When handling traffic that is destined for itself, the SRX examines the host-inbound-traffic configuration for the ingress interface and the associated security zone. It evaluates whether the traffic should be allowed based on this configuration. Traffic not addressed to the…
Question
Which two statements are true about the procedures the Junos security device uses when handling traffic destined for the device itself? (Choose two.)
Options
- AIf the received packet is addressed to the ingress interface, then the device first performs a
- BIf the received packet is destined for an interface other than the ingress interface, then the device
- CIf the received packet is addressed to the ingress interface, then the device first examines the
- DIf the received packet is destined for an interface other than the ingress interface, then the device
How the community answered
(35 responses)- A11% (4)
- B6% (2)
- C83% (29)
Explanation
When handling traffic that is destined for itself, the SRX examines the host-inbound-traffic configuration for the ingress interface and the associated security zone. It evaluates whether the traffic should be allowed based on this configuration. Traffic not addressed to the ingress interface is handled based on security policies within the junos-host zone, which applies to traffic directed to the SRX itself. For more details, refer to Juniper Host Inbound Traffic Documentation. When handling traffic that is destined for the SRX device itself (also known as host-bound traffic), the SRX follows a specific process to evaluate the traffic and apply the appropriate security policies. The junos-host zone is a special security zone used for managing traffic destined for the device itself, such as management traffic (SSH, SNMP, etc.).
Topics
Community Discussion
No community discussion yet for this question.